Source
Security / trust page — found from the homepage — FreeAgent
Checked for FreeAgent on 30 Sep 2026
- Page
- https://www.freeagent.com/features/security/
- Checked
- 30 Sep 2026, 13:15 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:8c0109824489e4d3d94d0f8f4eb829f5669e37df92406e65341ee025687c3897
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Data centres Report an error
“Our customers’ information is held securely in data centres located in Ireland across multiple availability zones to guard against localised, physical failure.”
-
Ddos mitigation Report an error
“Distributed Denial of Service (DDoS) mitigation is automatically applied by our hosting provider. Meanwhile, we employ in-built application rate limiting and alerting, which includes protection against brute force login enumeration.”
-
Password storage Report an error
“User passwords are stored in our database via a one-way cryptographic hashing function with salt (random data). Passwords are not stored in plaintext and it’s not possible to reverse engineer the stored value equivalent.”
-
Two step verification Report an error
“Customers can enable 2-Step Verification to provide a further level of protection.”
-
Internal two factor Report an error
“All access to FreeAgent’s underlying systems and data is protected through the use of unique credentials with two-factor authentication. Everything is logged and reviewed through an immutable, centralised audit trail.”
-
Third party sharing Report an error
“FreeAgent does not sell, rent or share data with any third party unless previously agreed as part of any contractual arrangement (or any legal or regulatory requirement).”
-
Security policies Report an error
“We also maintain a suite of internal information security policies, procedures and guidelines, including incident response plans, which all staff, contractors and third parties must follow. These are reviewed at least annually.”
-
Development practices Report an error
“Our developers are versed in the OWASP Top Ten critical web application security risks. All code must be peer reviewed and must then pass Continuous Integration automated testing, quality and security control gates before being merged and deployed through a Continuous Delivery process mechanism.”
-
Data resilience Report an error
“As well as having a highly available, fault-tolerant database underpinning the application, FreeAgent also has point-in-time recovery. Additional secured, offline daily snapshots of data are available should they ever be required.”
-
API Report an error
“FreeAgent API”
9 facts read from this page are not shown because they could not be confirmed on the page as captured.